Top 10 Takeaways from the New HIPAA Security Rule NPRM
On January 6, 2025, HHS proposed significant updates to enhance HIPAA cybersecurity protections, including new technical inventory, risk assessment, and vendor oversight requirements. The NPRM also mandates better incident response and compliance practices, with public comments closing on March 7, 2025.
Published on April 2, 2025
On January 6, 2025, the U.S. Department of Health and Human Services (HHS) unveiled a Notice of Proposed Rulemaking (NPRM) aimed at strengthening cybersecurity protections for electronic protected health information (ePHI). This update—marking the most significant change since 2013—introduces measures such as mandatory annual technical inventories, rigorous security risk assessments, enhanced vendor oversight with rapid notification requirements, and enforced multi-factor authentication (MFA) along with specific encryption standards.
Additional proposed initiatives include formalized incident response planning, disaster recovery, regular network testing and segmentation, workforce security access management, and annual compliance audits. The changes, driven by the need to reduce breach risks and bolster data security, were open for public comment until March 7, 2025, with over 4,000 detailed submissions reviewed by HHS.